IBM PowerVM Hypervisor FW950 LPM Traffic cryptographic issues

A vulnerability was found in IBM PowerVM Hypervisor FW920, PowerVM Hypervisor FW930, PowerVM Hypervisor FW940, PowerVM Hypervisor and PowerVM Hypervisor FW950 and classified as problematic. Affected by this issue is an unknown code block of the component LPM Traffic Handler. Upgrading eliminates this vulnerability.

Description

The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232.

CVE-ID

CVE-2021-20505

Risk Score 4.4
Severity rating: MEDIUM
CVSS Vector: AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Vendor IBM
Remote Access  Yes

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
PowerVM Hypervisor FW920
PowerVM Hypervisor FW930
PowerVM Hypervisor FW940
PowerVM Hypervisor FW950

Basic Matrices

http://artedgeek.com/s_ne.php Attack Vector: Network
Freguesia do Ribeirao da Ilha Attack Complexity: High
Privileges Required: High
User Interaction: None
Scope:  Unchanged
Confidentiality Impact: HIGH
Integrity Impact: None
Availability Impact: None
CWE CWE-310

Mitigation

Upgrade to eliminate this problem

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-24856 : LINUX KERNEL UP TO 6.8 ACPI_ALLOCATE_ZEROED NULL POINTER DEREFERENCE

CVE-2024-24856 : LINUX KERNEL UP TO 6.8 ACPI_ALLOCATE_ZEROED NULL POINTER DEREFERENCE

Description The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a successful allocation, but the subsequent code directly dereferences the pointer

CVE-2024-2912 : BENTOML FRAMEWORK UP TO 1.2.4 POST REQUEST INSECURE DEFAULT INITIALIZATION OF RESOURCE

CVE-2024-2912 : BENTOML FRAMEWORK UP TO 1.2.4 POST REQUEST INSECURE DEFAULT INITIALIZATION OF RESOURCE

Description An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted

CVE-2024-26817 : LINUX KERNEL UP TO 6.8.5 AMDKFD KZALLOC INTEGER OVERFLOW

CVE-2024-26817 : LINUX KERNEL UP TO 6.8.5 AMDKFD KZALLOC INTEGER OVERFLOW

Description In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid integer